LWTech CSNT231/232 Networking I & II

ASTL Enterprise Network Design

A comprehensive enterprise network design project focused on infrastructure planning, network segmentation, physical security, wireless networking, redundancy, business continuity, and scalable enterprise architecture.

Project Background

Project Overview

The ASTL Network Design project focused on designing a complete enterprise network infrastructure for a mixed office and warehouse facility. The design supports employee workstations, warehouse devices, printers, VoIP phones, wireless access points, badge readers, security cameras, server infrastructure, and cloud-connected business services.

The project required planning both the physical and logical environment, including structured cabling, network racks, Internet connectivity, VLAN segmentation, firewall policy, wireless networking, cloud integration, redundancy, security, and future expansion.

Design Objective

Create a secure, scalable, and maintainable enterprise network capable of supporting business operations, communications, physical security, cloud services, and future organizational growth.

Project Summary

Network Design at a Glance

A three-week enterprise networking project completed as part of the Computer Security and Network Technology program at Lake Washington Institute of Technology.

Institution

Lake Washington Institute of Technology

Instructor

Robert Havens

Completed

June 10, 2025

Duration

Three Weeks

Environment

Small-to-Medium Enterprise

20

Design Pages

Technical network report

8

Wireless APs

UniFi U7 Pro Max

2

Internet Providers

Primary & failover

14

VLANs

Department & service segmentation

VoIP Infrastructure

Dedicated voice network

Infrastructure Planning

Design Scope

The project addressed the physical, logical, wireless, security, and operational requirements of a complete enterprise network.

Physical Network Design

Designed infrastructure for a mixed office and warehouse facility with server rooms, network closets, employee workstations, wireless access points, VoIP phones, printers, cameras, and badge-access systems.

Cabling & Hardware

Planned Cat 6 cabling, fiber links, patch panels, keystone jacks, RJ45 termination standards, DAC cables, outdoor-rated cabling, rack infrastructure, and ISP handoff connections.

VLAN Segmentation

Designed segmented networks for accounting, development, office operations, security, management, marketing, records, sales, supply chain, servers, VoIP, guest Wi-Fi, and network management.

Security & Access Control

Planned firewall rules, ACLs, guest isolation, WPA3 Enterprise, RADIUS authentication, badge readers, CCTV, locked racks, visitor controls, and restricted access to sensitive spaces.

Platforms & Concepts

Technologies & Concepts

The design combined enterprise networking technologies, security controls, cloud services, wireless infrastructure, and physical security systems.

Cloud Services & SSO

Identity, collaboration, authentication, and hosted business services.

Firewall Rules & ACLs

Traffic control, segmentation, and least-privilege communication between network zones.

Cameras & Badge Readers

Physical security monitoring and controlled access to facility spaces.

UniFi Gateways

Dream Machine Pro Max and Pro SE gateways supporting separate network and VoIP infrastructure.

Switching & Aggregation

Core aggregation, access switching, PoE delivery, fiber uplinks, and structured expansion.

VLANs & Subnetting

Logical segmentation supporting security, performance, traffic management, and administration.

VoIP Network Planning

Separate voice traffic, dedicated gateway services, and quality-of-service planning.

WPA3 Enterprise

Secure corporate wireless access with centralized RADIUS-backed authentication.

Wireless Coverage

Enterprise access points, guest isolation, captive portal access, VLAN assignment, and roaming.

Core Design Decisions

Network Architecture Highlights

The architecture was designed around resiliency, centralized management, secure segmentation, wireless availability, and long-term scalability.

ISP Redundancy

Ziply Fiber served as the primary 10 Gbps connection, with Comcast Business providing failover connectivity. This supported business continuity if the primary connection became unavailable.

Hybrid Topology

The topology combined star, logical bus, mesh, and hierarchical design elements to support access switching, core aggregation, redundancy, structured growth, and centralized management.

Wireless Design

The wireless design included eight UniFi U7 Pro Max access points, WPA3 Enterprise for corporate access, RADIUS authentication, guest captive portal access, roaming, and VLAN isolation.

Physical Security

The design included locked racks, badge readers, CCTV, visitor controls, and access restrictions for sensitive areas including the server room, network closets, warehouse spaces, and secure storage areas.

Business Integration

Cloud & Business Services

The network design incorporated cloud and business services to support identity, collaboration, inventory management, remote access, backups, monitoring, and employee productivity.

UniFi Identity Enterprise

SSO, RADIUS, VPN access, identity services, physical access control, and centralized monitoring.

Microsoft 365

Email, documentation, Teams collaboration, productivity applications, and OneDrive backups.

Microsoft Azure

Identity integration, device monitoring, cloud resources, virtual machines, and infrastructure services.

Salesforce

Inventory management, order fulfillment, shipping, sales operations, and business workflow support.

Public Web Services

Customer-facing company information, online ordering, public resources, and the organization’s web presence.

Applied Knowledge

Skills Demonstrated

The project applied networking, infrastructure, security, and documentation skills across a realistic enterprise design scenario.

  • Enterprise Network Design
  • VLAN Segmentation
  • Firewall and ACL Design
  • Wireless Network Planning
  • Physical Infrastructure Planning
  • ISP Redundancy
  • Cloud Integration Planning
  • VoIP Network Design
  • Technical Documentation
  • Security Planning

Submitted Work

Project Deliverable

The following document was submitted as the final deliverable for the CSNT231/232 Networking I & II project.

Technical Design Report

ASTL Network Design Report

A complete enterprise network design document covering floor plans, structured cabling, network hardware, topology, VLANs, device communication, firewall and security controls, storage, virtualization, wireless networking, business continuity, and physical security.

Project Reflection

Lessons Learned

This project reinforced how much planning is required before network implementation begins. A successful enterprise network extends well beyond switches, routers, and cabling. It must also consider business workflows, physical security, wireless coverage, redundancy, cloud integration, future growth, and long-term maintainability.

Designing ASTL from the ground up strengthened my understanding of how infrastructure decisions affect scalability, resiliency, security, and the day-to-day experience of both users and administrators.

Continue Exploring

Interested in This Project?

Explore the rest of my portfolio to see additional systems administration, networking, cloud, and infrastructure projects, or reach out if you'd like to discuss my work.